question

yaarnaan avatar image
0 Votes"
yaarnaan asked JennyYan-MSFT answered

WinRM Filtering

Hello All,

I'm new to WinRM and the deployment, I have successfully made the Windows servers to log to a SIEM using WinRM, but I would like to know on how to filter out a particular event , using event ID as I don't want WinRM to send this event ID to my SIEM.

remote-desktop-serviceswindows-server-management
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

JennyYan-MSFT avatar image
0 Votes"
JennyYan-MSFT answered JennyYan-MSFT commented

Hi,
If you are using event forwarding to make the Windows servers to log to a SIEM using WinRM, you can define which events should be forwarded using the filter dialog in Event Viewer or with the XML query you see above for more advanced filters.
https://serverfault.com/questions/913015/where-are-windows-event-forwarding-wef-subscriptions-filters-applied

However the suppress statements which filter out specific events, only apply within that query statement and are not to the entire subscription.
https://docs.microsoft.com/en-us/windows/security/threat-protection/use-windows-event-forwarding-to-assist-in-intrusion-detection#baseline-subscription

Please note: Information posted in the given link is hosted by a third party. Microsoft does not guarantee the accuracy and effectiveness of information.

Thanks,
Jenny

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi,
Is there any update? Have you got a chance to verify above suggestions?

Please feel free to let us know if more assistance needed.

Thanks,
Jenny

0 Votes 0 ·
JennyYan-MSFT avatar image
0 Votes"
JennyYan-MSFT answered

Hi,
I am checking if there is more assistance needed for this thread.

Please feel free to revert back and kindly Accept as answer if the information provided is helpful.

Thanks,
Jenny

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.